Proton Mail vs Soverin

Compare Proton Mail and Soverin on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Microsoft 365, Outlook.com

Logo: Proton Mail

Proton Mail

Switzerland· Email Services

Needs review

Shortlist Proton Mail when you want Swiss-jurisdiction, zero-access encrypted email with open-source clients, custom domains, Bridge for desktop mailers, and a public DPA. Skip when you need free-tier IMAP Bridge, fully self-hosted FOSS mail on your own servers, or Workspace-class collaboration depth—consider Tuta, Posteo, or Mailfence among EU peers, or stay on Google/Microsoft if suite lock-in wins.

E2EE + zero-accessSwiss-operatedBridge (IMAP/SMTP)Open-source clientsISO 27001 & SOC 2 (claimed)Public B2B DPA
Logo: Soverin

Soverin

Netherlands· Email Services

Needs review

Shortlist Soverin when you want Dutch-operated, paid IMAP email with custom domains, unlimited aliases, and strong mail-auth standards without Google/Microsoft ads. Skip when you need zero-knowledge E2EE—consider Proton Mail or Tuta instead—or a full productivity suite (mailbox.org / Microsoft 365).

NL / EU operatedCustom domainsIMAP / CalDAVNo ads / no trackingISO 27001 (claimed)DANE / DNSSEC
Proton Mail vs Soverin: Snapshot
FeatureLogo: Proton MailProton MailLogo: SoverinSoverin
Country of originSwitzerlandNetherlands
CategoryEmail ServicesEmail Services
Open sourceNoNo
Self-hostedNoNo
HeadquartersSwitzerlandNetherlands
Legal entityProton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland (EU representative: Proton Europe sàrl, Luxembourg)Soverin B.V. (Amsterdam); owned by The Sharing Group / TSG Online (Dutch) as of September 2025 acquisition announcement
Governing lawSwiss law (Terms; Geneva courts for business/non-US consumer disputes as stated in Terms)Not listed
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyPrimary mail storage on Proton-owned servers in Switzerland (vendor security pages). Not marketed as AWS/GCP/Azure inbox hosting. Public privacy policy lists US-group processors for support and payments (Zendesk; Chargebee, Stripe, PayPal) and group support processing in North Macedonia and Taiwan; HubSpot noted for business sales inquiries.Vendor: EU-only processing; data in NL; self-operated Dutch DCs, no hyperscaler. TechRadar: 3 NL DCs. Core mail hosts on Soverin B.V. AS211993. External first-line support partner under DPA/NDA (country unpublished). HIBP k-anon password checks; Let’s Encrypt; domain DNSSEC partner. No AWS/GCP/Azure as primary mailbox hosts in public materials.
Summary

Swiss end-to-end encrypted email from Proton AG: zero-access inbox storage, open-source clients, custom domains, and Bridge for desktop IMAP clients.

Dutch privacy-first email hosting: custom domains, open IMAP/SMTP/CalDAV, 25 GB mailboxes, no ads or content scanning, servers operated in the Netherlands.

Tags
At a glance: Proton Mail vs Soverin
At a glanceLogo: Proton MailProton MailLogo: SoverinSoverin
HQPlan-les-Ouates (Geneva), SwitzerlandAmsterdam, Netherlands (Soverin B.V.)
Legal entityProton AG (CHE-354.686.492); Proton Foundation supervisionNot listed
Hosting modelProton-owned hardware in Switzerland (vendor claim)Not listed
Self-hostNo (SaaS); clients open sourceNot listed
Commercial modelFreemium + paid consumer and business seatsAnnual prepaid; 30-day mailbox money-back; no free tier
BridgePaid plans that include MailNot listed
GroupNot listedThe Sharing Group / TSG Online (acq. Sep 2025)
HostingNot listedDutch data centres; vendor claims self-operated, no hyperscaler
ProtocolsNot listedIMAP, SMTP, CalDAV, CardDAV
StorageNot listed25 GB per mailbox (vendor-stated)
Self-host / OSSNot listedNo / No
Key capabilities: Proton Mail vs Soverin
Key capabilitiesLogo: Proton MailProton MailLogo: SoverinSoverin
E2EE + zero-accessYesNot listed
Swiss-operatedYesNot listed
Bridge (IMAP/SMTP)YesNot listed
Open-source clientsYesNot listed
ISO 27001 & SOC 2 (claimed)YesNot listed
Public B2B DPAYesNot listed
NL / EU operatedNot listedYes
Custom domainsNot listedYes
IMAP / CalDAVNot listedYes
No ads / no trackingNot listedYes
ISO 27001 (claimed)Not listedYes
DANE / DNSSECNot listedYes

Proton Mail

  • Zero-access inbox encryption by default

    Bodies and attachments are encrypted so Proton states it lacks keys to read stored mail. Proton-to-Proton traffic is end-to-end encrypted automatically; external recipients need password-protected messages or PGP/WKD for comparable content protection. Subject lines are not fully E2EE under OpenPGP header rules.

  • Proton Mail Bridge for desktop IMAP clients

    Paid plans that include Mail can run Bridge locally to connect Outlook, Thunderbird, or Apple Mail over IMAP/SMTP while encrypting and decrypting on the device. Free accounts use official web/mobile/desktop apps instead of Bridge.

  • Custom domains, aliases, and business admin

    Paid and business tiers support custom domains, extra addresses, catch-all and groups, hide-my-email aliases, and org admin for seats, storage, and retention policies. Suits teams leaving Google/Microsoft who still need branded addresses.

  • Open-source clients with published audits

    Web, mobile, and desktop clients are published on GitHub with third-party audit reports linked from Proton’s open-source page. The hosted mail backend is not offered as self-hosted FOSS—audit client trust, not full server reproducibility.

  • Tracker blocking, PhishGuard, and Sentinel

    Built-in tracker protection, phishing heuristics, link confirmation, SPF/DKIM/DMARC for custom domains, hardware-key 2FA, and optional Proton Sentinel monitoring for high-risk accounts. Complements encryption with everyday abuse defenses.

Soverin

  • Custom domains with unlimited aliases

    Host mail on your own domain (bring existing or register through Soverin). Unlimited aliases—plus-addressing or domain names—deliver into one mailbox, plus optional random @sinenomine.email private aliases that hide the real address. Suits freelancers and SMEs who need brandable addresses without per-alias fees.

  • Open IMAP/SMTP plus CalDAV/CardDAV

    Use any standards-based client or device for mail, calendar, and contacts—no proprietary app required. Dashboard import helps migrate from other providers. Ideal when IT wants Thunderbird, Apple Mail, or Outlook without locking into a closed webmail ecosystem; not a zero-knowledge E2EE product by default.

  • Mail-path security: DANE, DKIM, DMARC, IP stripping

    Outbound and inbound paths use TLS; Soverin publishes and honours DANE/TLSA, signs with DKIM, publishes SPF/DMARC, enables DNSSEC on managed domains, and strips personal IP addresses from outbound headers. 2FA is available and can be admin-mandated. Buyers still need their own OpenPGP setup for end-to-end content secrecy with external parties.

  • 25 GB mailboxes with per-user encrypted backups

    Each mailbox includes a stated 25 GB quota covering mail, calendar, and contacts. Nightly backups use individually generated keys; Soverin states that emptying trash permanently deletes data and that leaving the service removes backups when the key is destroyed. Extra mailboxes can share storage for small teams.

  • Multi-mailbox and channel-friendly business use

    Purchase and assign additional mailboxes on a domain, with admin tooling for teams. Soverin markets to hosters, ISPs, MSPs, and independent professionals for multi-mailbox and white-label scenarios—useful when you want Dutch-operated email without building your own mail stack.

Assurance & compliance: Proton Mail vs Soverin
Assurance & complianceLogo: Proton MailProton MailLogo: SoverinSoverin
Independent security / client audits
Vendor claimed

Open-source clients with published third-party audit reports (web/desktop links on open-source page). Not a classic VPN no-logs court test; transparency report covers legal orders for accessible account data.

Not found

No public third-party no-logs or full security audit PDF located; privacy claims are first-party.

ISO 27001
Vendor claimed

Vendor announces ISO 27001 certification after external audit completed 2 May 2024; Trust Center links a certificate download. Confirm scope and validity at procurement time.

Vendor claimed

Vendor states independently audited ISO 27001; certificates available on request via support@soverin.net. Not re-verified against a public registry entry in this pass.

SOC 2 / SOC 3
Vendor claimed

Vendor announces first SOC 2 Type II attestation (July 2025 blog). Report typically under NDA—request from vendor for diligence files.

Not found

No SOC 2/3 claim found on primary pages reviewed.

GDPR / EU data protection
Vendor claimed

Swiss controller/processor with EU representative; public DPA; GDPR materials for business. Adequacy/transfer mechanisms documented for non-adequate destinations.

Vendor claimed

NL entity; AVG-framed privacy statement; EU-only processing claimed; GDPR Proof messaging on recognitions page.

US CLOUD Act exposure (indicative)
Partial

Swiss entity / no known US parent; inbox content on Proton-owned Swiss hardware with zero-access design. Partial exposure remains via US SaaS subprocessors (Zendesk support; Stripe/Chargebee/PayPal payments) and any account metadata Proton can access under Swiss process. Not legal advice.

Partial

EuropeanStack assessment: low exposure path—Dutch Soverin B.V., Dutch The Sharing Group owner, claimed self-operated NL hosting without public AWS/GCP/Azure mailbox hosts. Partial because residual subprocessors (support partner jurisdiction, domain partners, HIBP hash checks) need buyer confirmation. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Public DPA at proton.me/legal/dpa forms part of terms when Proton acts as processor; Swiss law, Geneva jurisdiction; general authorization for listed subprocessors.

Vendor claimed

Privacy statement states it qualifies as an Article 28 AVG processing agreement; other DPAs expressly rejected. Confirm signed annex for enterprise use.

EU AI Act
Not applicable

Core product is encrypted email. Optional Scribe assistant is ancillary; not an AI-centric offering for this catalog entry.

Not applicable

Email hosting product; vendor emphasises no AI scanning/mining of mailbox content for ads.

ISO 9001 / ISO 14001Not listed
Vendor claimed

Vendor-claimed quality and environmental certifications; certificates on request.

NIS2 readinessNot listed
Vendor claimed

Vendor markets NIS2 Ready; buyer press also asserts NIS2 compliance—confirm evidence package.

NEN 7510 (healthcare NL)Not listed
Partial

Vendor states NEN 7510 certification is in progress, not completed.

Considerations & known limitations: Proton Mail vs Soverin
Considerations & known limitationsLogo: Proton MailProton MailLogo: SoverinSoverin
Weaker defaults outside Proton
Medium

Mail to Gmail/Outlook/others is not E2EE unless password-protected or PGP/WKD is used. Subject lines are not fully E2EE. Train users or you only protect the Proton-stored copy.

Not listed
US support and payment processors
Medium

Zendesk, Chargebee, Stripe, and PayPal appear in the public processor list. They should not see zero-access message bodies, but support content and billing data can touch US-group services—document this in DPIAs.

Not listed
Bridge requires paid Mail
Low

Desktop IMAP/SMTP via Bridge is not available on free accounts. Budget seats for users who refuse the official apps.

Not listed
Hosted service, not self-hosted FOSS mail
Medium

Open-source clients improve inspectability but you still depend on Proton’s operated backend, uptime, and Swiss legal process. Unsuitable if policy mandates customer-operated mail servers.

Not listed
Swiss legal orders on accessible data
Low

Transparency reports show thousands of yearly legal orders for Mail with many complied. Bodies stay encrypted; recovery emails, IPs (when retained for abuse), and similar metadata may still be in scope. Align expectations with counsel.

Not listed
Not zero-knowledge E2EE by defaultNot listed
Medium

Unlike Proton/Tuta, Soverin is a classic IMAP host. Provider infrastructure can process content for delivery and spam filtering. Practical impact: unsuitable as a drop-in for policies that require provider-blind encryption without extra client crypto.

Unnamed external support partnerNot listed
Medium

Privacy statement discloses a first-line support partner with limited account data under DPA/NDA, but does not publish the partner name or country. Practical impact: add an open diligence item for any regulated workload.

ISO certificates not self-serve publicNot listed
Low

ISO 27001/9001/14001 are claimed with certificates via support rather than a public PDF registry link found in research. Practical impact: procurement should request current attestations before treating certs as verified.

2025 group acquisitionNot listed
Low

The Sharing Group acquisition may change subprocessors, tooling, or brand packaging over time even if continuity is promised. Practical impact: re-check DPA and hosting annex annually.

Email-centric supportNot listed
Low

Public materials emphasise human Dutch-team email support; TechRadar notes no live chat or phone. Practical impact: large orgs needing 24/7 phone SLAs may find coverage thin.

Fit

Proton Mail

Best fit when

  • Teams that need default end-to-end / zero-access encryption without running their own mail stack
  • Orgs that want Swiss legal venue and documented resistance to direct foreign data demands
  • Businesses migrating branded domains off Gmail/Outlook with Easy Switch and Bridge for desktop holdouts
  • Security-conscious professionals who value open-source clients, published audits, and hardware-key 2FA
  • Buyers who need a public DPA plus vendor-claimed ISO 27001 / SOC 2 Type II for questionnaires

Poor fit when

  • Fully self-hosted requirements (Proton Mail is SaaS; clients are open source, not a full on-prem mail server)
  • Desktop IMAP on free accounts only—Bridge needs a paid plan that includes Mail
  • Workflows that depend on unencrypted-looking mail to external parties who will not use password links or PGP
  • Teams that primarily need full Microsoft 365 / Google Workspace collaboration depth rather than encrypted mail first

Consider instead when

  • When: You want German E2EE email with a different crypto product surface and may not need Proton’s full ecosystem

    Consider: Tuta

    Compare desktop interoperability and business admin maturity side by side.

  • When: You want ad-free European mail with strong transport privacy but do not require zero-access E2EE for all stored content

    Consider: Posteo

    Different threat model: Posteo is privacy-forward without Proton’s zero-access default.

  • When: You need OpenPGP-centric mail with classic collaboration extras under Belgian operation

    Consider: Mailfence

    Weigh automatic Proton-to-Proton E2EE UX versus Mailfence’s model.

  • When: Collaboration suite depth and ecosystem lock-in outweigh encryption defaults

    Consider: Google Workspace or Microsoft 365

    Accept US-provider jurisdiction and scanning/processing models as tradeoffs.

Soverin

Best fit when

  • Individuals and freelancers who want a paid European mailbox on their own domain with any standard mail client
  • SMEs needing several mailboxes, aliases, and CalDAV/CardDAV without adopting Google Workspace or Microsoft 365
  • Teams prioritising Dutch jurisdiction and claimed no-hyperscaler hosting over zero-knowledge E2EE
  • Hosters/ISPs/MSPs evaluating white-label or multi-mailbox Dutch email
  • Buyers who value DANE, DKIM/DMARC, DNSSEC, and IP-header stripping on an open-standards stack

Poor fit when

  • Organisations that require default zero-access / E2EE mail against the provider (use Proton Mail or Tuta)
  • Users seeking a free tier, anonymous cash-only signup, or purely self-hosted open-source mail servers
  • Enterprises needing SSO, eDiscovery archives, phone support SLAs, or a full office suite in one vendor
  • Workloads that depend on US-region mailbox hosting or hyperscale global PoPs

Consider instead when

  • When: You need zero-knowledge E2EE and a privacy-first mobile/web ecosystem

    Consider: Proton Mail or Tuta

    Trade open IMAP convenience for stronger default content secrecy vs the provider.

  • When: You want German-hosted paid mail with broader office-style add-ons

    Consider: mailbox.org or Posteo

    Compare storage, admin features, and payment anonymity (Posteo) against Soverin’s domain/alias model.

  • When: You need Google- or Microsoft-class collaboration and global free consumer mail

    Consider: Gmail or Microsoft 365 / Outlook.com

    Different risk and advertising model; not EU-sovereignty substitutes.

Open questions for due diligence

Proton Mail

  • What exact data-center sites and any non-Swiss regions apply to your tenant’s mailbox replicas today?
  • Will Proton provide the full SOC 2 Type II report under NDA and confirm ISO 27001 certificate scope/expiry for your questionnaire?
  • For business orgs: which users will be private vs non-private, and how will admin recovery work with zero-access constraints?
  • Which external partners must receive E2EE content, and will they accept password-protected messages or PGP?

Soverin

  • What is the legal name and country of the first-line support partner, and is a current subprocessor list available under NDA?
  • Can Soverin provide the latest ISO 27001/9001/14001 certificates and scope statements without delay?
  • After The Sharing Group acquisition, are any new group companies (e.g. Mijndomein, Greenhost, Leafcloud tooling) in the mailbox data path?
  • Is NEN 7510 certification complete for healthcare use cases, or still in progress?
  • Which domain registrar(s) handle customer DNSSEC, and where are registry data stored?